S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-13942 Scanner

CVE-2020-13942 scanner - OGNL Injection (Object-Graph Navigation Language) vulnerability in Apache Unomi

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-13942
9.8
CVSS

It is possible to inject malicious OGNL or MVEL scripts into the /context.json public endpoint. This was partially fixed in 1.5.1 but a new attack vector was found. In Apache Unomi version 1.5.2 scripts are now completely filtered from the input. It is highly recommended to upgrade to the latest available version of the 1.5.x release to fix this problem.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache Unomiby Apache Software Foundation
AFFECTED< 1.5.2SAFE ✓≥ 1.5.2
Updated Aug 21, 2026View on NVD →
Detail

Apache Unomi is a popular open-source customer data platform that is used to collect, store and manage user data from various sources. It provides a centralized location for businesses to organize and analyze data, helping them to better understand their customers and provide personalized experiences. The platform is highly adaptable and can be easily customized to suit specific business needs. It boasts a range of features, including segmentation, personalization, and real-time analytics.

The CVE-2020-13942 vulnerability is a critical security flaw that was recently discovered in Apache Unomi. This vulnerability concerns the /context.json public endpoint, which is susceptible to malicious OGNL or MVEL scripts injections. Although this flaw was partially resolved with version 1.5.1, a new attack vector was found in version 1.5.2. The issue completely filters all scripts from the input to protect against script injection attacks.

When exploited, this vulnerability can lead to unauthorized access to sensitive user information stored on the Apache Unomi platform. This can compromise customer privacy and breach data protection regulations such as GDPR. Attackers can potentially gain access to login credentials, banking information, and other sensitive data and exploit it maliciously. This flaw poses a significant threat to businesses that rely on Apache Unomi to collect user data.

In conclusion, thanks to the pro features of the s4e.io platform, businesses can easily and quickly learn about vulnerabilities in their digital assets. Identifying and addressing security flaws early is essential to ensure business continuity and customer trust. The platform utilizes advanced scanning and testing techniques that can identify key vulnerabilities in web applications, databases, and other digital assets. It provides businesses with detailed reports and recommendations to help them strengthen their security posture and protect against potential attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, businesses can take the following precautions:

  • Upgrade to the latest version of Apache Unomi 1.5.x.
  • Use a Web Application Firewall (WAF) to detect and block malicious traffic.
  • Enable input validation and sanitization checks to filter out malicious scripts and other security threats.
  • Restrict access to the /context.json public endpoint and other sensitive areas of the platform.
  • Implement multi-factor authentication for user logins to reduce the risk of password theft.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-13942 scanner - OGNL Injection (Object-Graph Navigation Language) vulnerability in Apache Unomi | S4E